CKS System Hardening Practice Question
A security engineer is hardening a cluster and wants to reduce the attack surface of Pods by restricting their access to host resources. The engineer is reviewing a Pod specification and plans to remove or disable settings that grant host-level access. Which two settings should the engineer remove or set to false to reduce the attack surface? (Choose two.)
⚠ Common exam trap
The trap here is focusing on privilege escalation or filesystem writability instead of the host namespace flags that actually grant host resource access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
hostPID: true
The hostNetwork and hostPID fields, when set to true, place the Pod in the host's network and PID namespaces respectively, giving it direct access to host resources and significantly increasing the attack surface. Removing or setting these to false isolates the Pod. The other options either represent secure settings that are already in place or address different security concerns not directly related to host resource access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
allowPrivilegeEscalation: true
Why it's wrong here
allowPrivilegeEscalation: true is an insecure setting, but it does not directly grant host-level access like host namespaces do. It allows a process to gain more privileges, which is a risk, but the question specifically targets host resource access. The correct settings to remove are the host namespace flags, not this one.
- ✗
readOnlyRootFilesystem: false
Why it's wrong here
readOnlyRootFilesystem: false means the container's root filesystem is writable, which is less secure than true, but it does not grant access to host resources. The question focuses on host-level access settings. A writable root filesystem is a separate concern from host namespace sharing, so this is not one of the two settings to remove.
- ✓
hostPID: true
Why this is correct
Setting hostPID to true places the Pod in the host's PID namespace, allowing it to see and potentially signal all processes on the node. Removing this setting or setting it to false isolates the Pod's process namespace, preventing it from viewing or interacting with host processes. This significantly reduces the attack surface.
- ✓
hostNetwork: true
Why this is correct
Setting hostNetwork to true places the Pod in the host's network namespace, giving it direct access to the host's network interfaces and allowing it to see all network traffic on the node. Removing this setting or setting it to false isolates the Pod's network stack, reducing the attack surface by preventing it from sniffing or interfering with host network traffic.
- ✗
privileged: false
Why it's wrong here
privileged: false is already the secure setting; it does not grant host-level access. The question asks for settings that grant host access and should be removed or set to false. Since privileged is already false, it does not need to be changed to reduce the attack surface. Setting it to true would increase risk, but that is not the scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.